We kicked off with a straightforward explanation of what the dark web actually is. Tony clarified the distinctions between the open web (the visible internet we all use daily), the deep web (pages that aren’t indexed by search engines and require authentication, like online banking portals), and the dark web.
The dark web is a hidden section of the internet that’s intentionally obscured and often requires specific software, like Tor, to access. While it’s not exclusively for criminal activity, the dark web is a hub for illegal activities, data trading, and stolen information—everything from personal credentials to corporate data can be bought and sold there.
Tony shared why MSPs should be particularly concerned about dark web monitoring. He emphasised that most MSP clients don’t realise just how vulnerable their data is or how easily it can end up on the dark web after a breach. He recounted how MSP Dark Web was born out of frustration with other vendors and security tools, which weren’t doing enough to protect his clients.
Now, his platform allows MSPs to monitor their customers’ domains and personal emails to detect stolen credentials and alert clients before damage is done. With Tony’s dark web monitoring service, MSPs can see if sensitive client information is being circulated on the dark web and act quickly to advise their clients on securing or updating their credentials.
One of the core themes we discussed was how to present this information to clients. For many business owners, technical jargon about dark web monitoring or data breaches goes over their heads. Tony shared that MSP Dark Web provides a comprehensive marketing toolkit for MSPs, which includes email templates, leaflets, and other resources to help MSPs communicate the importance of dark web monitoring in a simple, understandable way.
This helps MSPs position dark web monitoring as a proactive, essential service that can protect businesses from potential cyber threats.
During our chat, Tony highlighted a sobering statistic: his database contains 149 billion emails and 88 billion passwords from data breaches worldwide, and this number grows every day as new breaches occur. His platform also tracks “session cookie data”—which can allow attackers to access accounts even if two-factor authentication (2FA) is enabled.
This was a real eye-opener, and Tony advised listeners to avoid the “remember me” option on websites and to regularly clear their browser’s cache and cookies. These steps may seem small, but they can make a big difference in protecting your information from dark web exposure.
Another crucial point Tony shared is the importance of educating clients about the risks associated with reusing passwords. If a password is stolen from one site and a client uses that same password elsewhere, cybercriminals can potentially access multiple accounts. Dark web monitoring allows MSPs to detect compromised credentials in time for clients to change their passwords, rendering the stolen data useless.
We also delved into the misconceptions around cybersecurity stacks, particularly the tendency of MSPs to “stack fiddle,” as Paul Green has called it. This occurs when MSPs add endless layers of security tools without a cohesive strategy.
Dark web monitoring doesn’t necessarily overlap with other cybersecurity measures in an MSPs stack; it complements them by focusing on external threats. Rather than just looking at data within a business, dark web monitoring looks outward, alerting MSPs to information that might have been exposed in breaches they wouldn’t otherwise be able to track.
Towards the end of the episode, Tony emphasised the growing importance of dark web monitoring for everyone—not just those with large bank accounts. Cybercriminals don’t just target wealthy individuals; anyone can become a victim. For instance, attackers can exploit simple pieces of personal information, like a preference for dogs over cats, to manipulate victims. This was a stark reminder that every MSP should consider dark web monitoring as an essential part of their security offering.
In summary, Tony Capewell made a compelling case for why dark web monitoring is a must-have service for MSPs. It’s not just about selling a new tool; it’s about proactively protecting clients and building trust. With resources like MSP Dark Web, MSPs can offer their clients peace of mind by ensuring that if their data does appear on the dark web, they’re immediately informed and can take action to secure their information.
If you’re an MSP looking to strengthen your cybersecurity stack and communicate its value to clients, dark web monitoring could be the solution you need.
Connect with Tony Capewell through their website by clicking HERE
For full details of our Business Blueprint Workshop on Tuesday 3rd December, click HERE.
Connect with Ian HERE on LinkedIn and also Stuart by clicking this LINK
If you’re ready to take the next step in supercharging your MSP, take the Scale with Confidence MSP Mastery Quiz. This tool is designed to help you understand where your MSP stands and what steps you can take to scale profitably and effectively. This will provide you with insights and guidance tailored to your specific needs.
OR to join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE
Until next time, look after yourself and I’ll catch up with you soon!
IAN: In this episode of the it experts podcast, we help you understand what is the dark web and why should you actually be monitoring it?
INTRO: Welcome to the IT Experts podcast. The only podcast to help MSPs scale to 1 million and if already there, get to 5 and go fast. At the end of the day, isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.
IAN: So good morning, good afternoon, good evening. Welcome to the IT experts podcast. Got a great show today for you geeks. You're going to love this one. This is shiny ball syndrome all over the place. This is almost like it almost said, say the P word now, but this is tech all over this one. I'm going to introduce to you right now. Good morning and welcome to the show, Tony Capewell from MSP dark web. How are you doing today, Tony?
TONY: I'm doing very well. Thank you.
IAN: Good stuff. So we're going to talk today. Tony runs a business. He's going to explain and introduce himself in a minute. But we're going to be talking about an amazing platform that they've built that helps you monitor the dark web. So if you don't know what the dark web is, if you've heard about it, but you don't really know why it relates to an MSP then you need to stay tuned for this one because it's going to be an absolutely cracking show before we get cracking. Tony, Give us a little bit of a rundown. Who are you, what do you do and who do you help?
TONY: So I've been in the IT industry for too long nearly 30 years. I've originally ran I do run an MSP alongside MSP dark web that has now been running for about four years,
IAN: Good stuff and how did this passion project come about? Cause it's now turned into a great fledgling business, isn't it?
TONY: It certainly has. Yeah. Had an experience with another vendor that wasn't too great. And towards the end of lockdown, we decided that we would look into the feasibility of building our own dark web scanning platform. And four years down the line, we've got nearly 200 MSPs globally.
IAN: Nice. And what does the product do? This isn't necessarily about the product. I've just said this is not going to be a pitch. Now I'm getting into pitch the product. What's the outcomes of the product itself? And we'll get into that. So...
TONY: Yeah, in summary, it allows an MSP to monitor their customers domains and any personal email addresses that they may have for directors or shareholders of business. And our system will go out and search the dark web for any breaches that have occurred where stolen credentials, email address and password combinations have been leaked onto the dark web and are available for criminals to pick up and then utilize that information for identity fraud or. more sinister where they're stealing money from individuals or from companies.
IAN: So personally, as well as a business point of view, this is a serious thing. We've heard about the dark web. It comes into the security shiny ball, which as we know, if you go to any event in the last two or three years, the amount of security vendors that have popped up is incredible the amount they are and I know I'm not technical. So you're in absolutely complete safe hands here. Tony, I could say something completely stupid. And you can just ignore it. But yeah, lots of security vendors. Yeah. Is that because MSP, some people think that MSP should be going in to sell their products and services on fear. Is it because it's the latest thing, that's a quite an easy thing to put a platform together. And before, you've got some information you never had before, but in this show, we're going to help you understand, what is the dark web and why should you monitor it? And the purpose behind the passion of creating this business. So Tony, most of us have probably got a fair idea on what the dark web is, but what is it? What's the difference between the dark web and the deep web and the open web? And there's all these other types of different webs out there, isn't there? And give us, let's just hear it from the horse's mouth. What's it all about?
TONY: Okay. What everybody knows day to day is the open web, which is what we use Google for, we use Google to search, find information, people's websites and various information that we use day to day BBC, Facebook, whatever it may be. The deep web is a vast portion of the internet that's not indexed by the search engines. It includes content that is hidden behind login forms, paywalls or other types of access controls. Examples of this are like online banking pages, private corporate websites, medical records, government databases. So that's the deep web. And then the dark web is a small intentionally hidden part of the deep web that requires specific software. A different browser that will allow you to go in and view those websites. That are then hosted and stored on the dark web. These special tools, tool browsers peer to peer tools, et cetera, are what are available for people to use that platform to then find the information that they want.
IAN: So they can access, the data that's in there which just bemuses me, really. This is bad guy territory, right? Isn't it? Nothing good happens in the dark web. Is that a fair assumption?
TONY: Fair assumption.
IAN: A fair assumption. Not a lot of good stuff goes on in the dark web, hence the name.
TONY: It's also used for the likes of sort of whistleblowing sites. So if people are wanting to share something with anonymity, they can, whistleblowers. It's not necessarily all about bad criminals, but it is. Predominantly made up with what is known as criminal activity,
IAN: Right, okay. ‘Cause I want to know, cause I'm interested who, who owns it? Who's hosting this? How does it kind of work? Is this all just to do with these peer networks or is this something more bit more technical that there's no chance we're going to cover it off in the next 30 minutes?
TONY: Yeah, it's quite complicated, but You could set up a server that serves data on the dark web from your home address. Obviously it's trackable, but these criminals, these cybercriminals, that are all, are running some of these huge, big sites. Yeah. It's much more complex. Yeah. But anybody if you have peer to peer software tools running on your workstation, your Mac or your PC sitting in your house, then those tools are accessing the dark web. And equally on a peer to peer network, your device is becoming part of the dark web.
IAN: Okay. So we got the dark web. We've got a lot of bad information on there. There's a possibility that you or your customer's data could be on there, which means that if we actually find out about it, then we can change it. And then it becomes obsolete. I'm guessing that's the kind of The simplest isn't it? So what is dark web monitoring then? If it's one of these things that's hidden in the corner of the internet, how can you go in there and find out what's on it?
TONY: There's some automation that occurs. So we have a combination of automated bots that will go out and source and look for information that's on the dark web. We also then have a security team. from our data source that will actively, if there's a breach that they're aware of, so I don't know.
Let's just take an example, say Virgin airlines, let's just say one of their databases, which has got all of their passionate information was breached and that information is stolen and then dropped onto a site within the dark web and has Joe blocks. email address and his password that he not only uses on Virgin, but he also uses on his Amazon account. He uses it on his Facebook account. He uses it here, there and everywhere. So the criminals will sell that data for very small amounts of money, but they'll sell it over and over again. And some of those criminal groups will be small, some possibly individuals, but, and they'll have automated tools that will use that data to then try and get access to those accounts. Once they get access, then within those accounts, for example, on your, on a Virgin account, you may have your passport number in there. You've got your date of birth, you've got various information, possibly your credit card information, so on and so forth. A breach that occurs is not necessarily the individual. It's the site that has been breached. And therefore the credentials that you stored in that site are then available on the dark web.
IAN: So what can we, once we've got this information and you've, and I'm guessing that this comes up in your reports, in your analysis, in your tools, is it? Or which I'm guessing, and I know that there are, there are other dark web monitoring tools out there. But this will ping up emails. So this will not just be for yourself. You could, as an MSP, we know that, they're high target. They're high value to the bad guys to get that. Does it work? Does the dark web monitoring work that it would then cascade down all the way down through the tree of your own clients and all the way through your PSA databases and all of that sort of thing, or is it a bit more complicated?
TONY: So the, yeah, so the way it will depend on the general public will use an email address and password combination for one site on multiple sites is piece of information that is stolen from divergent airlines may not necessarily be sufficient for them to commit any fraud against that individual. But if they can gain access to the multiple sites and get as much information about those, that individual,
IAN: Yeah.
TONY: They build up their own profile, which then will allow them to attempt to commit some kind of fraud on that person. If they get enough hits and that is for the criminals, that's an automated process. There's not like someone sitting there just trying to log in one by one to everybody's accounts. Cause there's a, there is. millions of records of data. But for the MSP what our platform does is it allows them for their customers. It allows them to put their customers domain in, and then we use that domain to go and search our database to see if there is any records. And we populate new breaches anywhere between five and 10 new breaches on a daily basis into the database. So that's how big this is and how much how many records. I'm not sure what the total number of records are in the database. So I'll ask new in a second to grab that for me and get the number. But it is growing on a daily basis.
IAN: So if someone's got yours or your client's credentials And this might be a stupid question and you've got two FA set up on your Santander banking app can I still get into it?
TONY: I can yeah, so session cookie data is something that we are currently Looking at so we are collecting session cookie data and session cookie data is the when you go to a website, your browser will store a session cookie and that information. If you say if you log into your account and you say storm. I remember me. for the next seven days, right? That stores a cookie in your browser and that data then can be is also stolen. And we're collecting that at the moment. And we're just currently working out how we can tie that stolen session cookie data to the individual's email address and or device that we collected within the data that we've got on the dark web.
IAN: So is that tip number one from today? When it says click and remember me for the next seven days, don't click it. I never do. No, that's the good recommendation.
TONY: Yeah, don't, never tick it. But if you do tick it, just make it a regular occurrence to clear your browser cache out all the time, and session cookies, etc. Because then, which is quite annoying there's obviously when you load up the website again, you've got to log in and so on and so forth, but then using a tool like a password tool that keeps your password safe and also allows you to then log into websites using the password manager. That is a much easier processing. You don't have to remember logins for each site. So I've just been handed a piece of paper. So currently we have a hundred plus 149 billion emails in our database and 88 billion passwords. And when we say passwords, that means that we have whether they're encrypted or not, we've unencrypted them and we have them in plain text.
IAN: Oh, crikey. I need to have a chat with you when we stop recording, just to have a quick look and see. So this is obviously something that an MSP can use proactively to talk to their clients or offer as a service, isn't it? Is that the opportunity here that they can literally just buy this product? And then the MSP needs to explain why it's important to them, because we know that most MSPs have quite a bit of a hard time getting explaining non technical business benefits to running IT businesses rather than the technical side of things. So what's some of the language that you would suggest an MSP uses to enable this to be a sales opportunity?
TONY: We have built an entire marketing dump for you. So anybody that signs up to our service will receive the full suite of marketing that we have, which gives them the ability to run an email campaign posters, leaflets, et cetera, that they can use as part of their sales process. The platform has a prospecting tool, which will allow the MSP to run a prospecting report, which has limited results, but gives totals of, for that particular prospects domain it will give them the number of records that we've got stored in our database. And how many email addresses, how many passwords that we have in the database, and it will return for them on a nice report, the top five most recent breaches in the top five, most severe breaches that gives the MSP a nice little report that they can either encompass into their own material for when they're proposing a managed service to their customer. Or they can use it as an individual tool to go and talk to that client. If they're already talking to them about dark web scanning and how, why it's important, et cetera, et cetera.
IAN: Yeah, okay, cool. Let's crush some myths right now. So we've got we're working with a lot of MSPs and there's a real been a real over the last six or eight months, six, yeah, six, six, nine months, there's been a real security focus, I as me cybersecurity essentials, what you need to do building this thing. And when we had Paul, we're just talking about our great friend, Paul Green. When we had Paul at our client intensive a couple of weeks, he came up with this phrase that It's never been repeated, so I should repeat it again. And he said, all you MSPs, you love stack fiddling, don't you? It's all about fiddling around with a stack, which I thought was absolutely brilliant.
TONY: I was listening to, he was on a podcast the other day, actually, and he said it again, stack fiddling. Yeah.
IAN: I thought I was going to coin that one. I'll have to have a chat about that. Anyway, what is Stackfiddling?
My perception of Stackfiddling is, ah, we've got cyber security sensors. Yes. I've got some, monitoring software. I've got this in place. I've got that. I've been to an event. I've bought another one. And then before you know it, you've got this massive big pile of. Security stack that probably some of it actually conflicts with itself. Some of it duplicates, the services and the, not the services the functions of it duplicate themselves because, people are always developing, the vendors are always developing the software and they might now do something. So you've got this whole stack that's stuck to your system with the antivirus and the anti malware tools and all this, do you, why, what is, why is this any different to picking up all of those what we would call a standard?
TONY: This is nothing to do. Dark web is nothing to do with the device effectively. The data that's available on the dark web is not necessarily down to the individual and what they've done on their computer, whether they've clicked on the wrong link or whatever. It's more about, like we said earlier, a big corporation that's been hacked. And the data that is stored within there is about the individual. So me, a big airline could have my data, your data, and probably all of your MSPs data on there, because they've all used that popular airline. No, one's done anything wrong other than the airline.
IAN: Okay. Yeah.
TONY: It's then but then that, that stolen data that is available in there. If the individual, for example, if you use your email address and the same password on your airline site, and you use that same password to log into your 365 account, which has access to your emails and various other applications. Then if you're targeted, there's a risk that you could then be hacked into. That could be monitoring your emails over a period of time, looking to see take an opportunity of when you're making a big payment to a supplier or so on. And they can interject that email and just say, Oh, by the way, and it looks like it's come from you, you would have no idea. Oh, by the way, with bank details of change before, it, a large payment that you were supposed to pay to your video crew has now gone to someone else, not yet. Yeah.
IAN: So just, I know we said, how does it work at the beginning of the show? But does it, do you have to monitor it every day? Is it something you have to keep running this? Is it something that just runs in the background and when breach pop up?
TONY: It just runs in the back. It runs in the background. So we ingest new breaches into the database on a daily basis, as I said, say between five and 10 new breaches on a daily basis. And each of those breaches contains a number of records, generally hundreds of thousands, if not millions. With the MSP running the monitoring within our platform, we're actively, as soon as that breach is ingested into our system then we will alert the MSP via their PSA tool of any new breaches that have occurred that have been listed in that new breach that's been ingested or those list of breaches that have been ingested into the platform. So today, if there was a new breach come in and. MSPA, they've had, they've got a customer's domain that's listed a hundred times in that breach. Then they'll get a notification, say your customer has been listed in this breach. And we give them a, the breach has a severity level, and that's based on how much information is in that breach for that individual. And then it's down to the MSP then to speak to the individuals that has been listed. And get them to try and locate the site that is related to if we haven't given the information but anywhere where they use that email address and password combination needs to be changed because, and then you're, and then you're mitigating that data becomes useless.
IAN: Yeah. Is it as simple as that? Is it literally as simple as soon as it gets alerted, you just change your email address and then that combination doesn't work.
TONY: Change your password.
IAN: Oh, sorry. Change the password. Yeah.
TONY: Change your password and that email address and password combination. If that doesn't exist anymore, then the data that's on the dark web useless.
IAN: Now I'm asking this for a friend, right? You got an iPhone?
TONY: I don't I don't.
IAN: Yeah, you don't use an iPhone. On the iPhone, someone told me once that every now and then, or quite often you get a little thing coming up that says, Hey, your phone, these this password combination has been found in a security breach, but it's literally every single blooming day this comes up for this mate of mine.
Is this something that, you know, because are Apple doing this thing within the Apple products and Android with it within their price? Is that a similar thing?
TONY: It is very similar. Yeah. There's a lot of products out there. A lot of password managers are now integrating some form of dark web. Protection scanning. But what they're doing is they're looking specifically for the email address and password that you've saved in the password manager. So what we are, what we're doing is we're doing it at the domain level. So we are not, we're not just specifically looking for that email address and password combination. We are looking in our breaches, we are looking to see if there is any entry in that breach for that domain. So we've got, we're moving, we've got a new UI coming out very soon and we're adding in a lot more information. So there will be an advanced service which will allow MSPs to not only find email address and password combinations that are listed on the dark web, but another 230 odd personal identifier with information. So okay driving license credit card information whether they like a cat or whether they like a dog whether they're what color their favorite color, we have a whole host of events and It may seem immaterial that you like dogs rather than cats, but if you're an avid dog lover and you will do anything for your dog and you get a phone call from someone and they start talking to you about a sad scenario with a dog and they're like, yeah, it's just going to cost you 50 quid just to help out these poor dogs. You might pay 50 quid.
IAN: Yeah.
TONY: Yeah. And if they do that over and over again. That's...
IAN: How do you sleep at night?
TONY: I'm not the... I'm not the criminal here.
IAN: I know you're not the criminal, but unless you've got everything all bolted down, it's Oh my God, someone's going to end up coming in the back door mentioned it before, but a bit of a shiny ball. Is this, who's this ultimately for, who needs to be doing this? Is it the MSP? Is it the end user? Is it just people who've got a lot of money in the bank? What's the best practice for this?
TONY: Like I said, it's not necessarily about the individual having loads of money. You may not have a load of money, but you might pay 50 quid for the poor dogs that have got no homes or whatever the scam may be. So it doesn't necessarily have to be targeted at any, anyone that's got lots of money, but it is.
Relevant for everybody. Cybercrime grosses more money annually than any other crime put together. Yeah. And he's growing.
IAN: And on that point that drops the mic.
Tony, thanks very much today with your time preparing for the show and also sharing those stats and information about the dark web monitoring. As I mentioned many times before, I'm not techie and I get it.
So that's really good. So we did a great job there. So any MSP should be able to go and provide this solution only for themselves, but also for other people. What's the big summary takeaways from today's show? What's everybody got to do once they hit the stop button on this podcast?
TONY: My view, my opinion is all MSP should have dark web scanning in their stack. We offer it a very low entry point. But it should be something that everybody has in their stack for sure.
IAN: Simple as that. And here comes the shameless plug now. I'm going to ask Tony to share if you want to get in contact with Tony and have a conversation about their solution and their platform and how it works.
But the one thing I'd really love you to do, if you do that, can you please just say to Tony, we heard you on the podcast, you were amazing. And I want to talk to you about your dark web monitoring. So how do people get in contact with you, Tony, if they want to continue the conversation?
TONY: Really simple. So just head over to our website, which is msp.web.com.
IAN: Easy as that.
TONY: Easy as that.
IAN: Hit the buttons and away you go. Once again, thanks ever so much for your help today. Really great show. Really enjoyed it. And I look forward to catching up with you soon. You take care.
TONY: Thank you very much.
OUTRO: Wait, wait, wait, just before you go, and if you're curious about how this episode links with the ability to scale your MSP to a million or if you are already there, accelerate to five, then we want to invite you to come and take the MSP Mastery quiz, and in just three minutes, you're going to get 360 degrees scan of your business where you can identify the one or two tactics that can help you find more time engaging along your people and help generate more leads in your MSP. It's really simple. Just click on the link in the show notes. And if you have enjoyed this episode, we'd love to get some feedback from you by means of a rating review on Spotify your podcast platform of choice. We really appreciate every single one of them. Now you can go and enjoy the rest of your day and we look forward to catching up and connecting with you soon. All the best.
OUR TRUSTED FRIENDS OF THE GROWTH HUB